Improper Access Control in ServiceNow AI Platform
CVE-2026-86858

8.7HIGH

Key Information:

Vendor

Servicenow

Vendor
CVE Published:
24 September 2026

What is CVE-2026-86858?

An improper access control vulnerability in ServiceNow's AI Platform could allow unauthorized users to create, modify, or delete instance data. This issue was remediated through an important security update released in August 2026. Users are urged to apply the update promptly to ensure their systems are protected against potential exploitation. ServiceNow has not reported any known malicious exploitation of this vulnerability, but proactive measures are essential for safeguarding sensitive information.

Affected Version(s)

ServiceNow AI Platform 0

ServiceNow AI Platform 0

ServiceNow AI Platform 0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.